What the rejection typically looks like
Guideline 3.1.1 - Business - Payments - In-App Purchase
We noticed that your app includes or accesses paid digital content, services, or functionality by means other than in-app purchase, which is not appropriate for the App Store.
Specifically, your app's Premium plan can be purchased on your website through a button in the app.
Next Steps
The paid digital content, services, or subscriptions included in or accessed by your app must be available for purchase in the app using in-app purchase. Remove buttons, external links, or other calls to action that direct customers to other purchasing mechanisms where they are not permitted.
Paraphrased example – the exact wording in your message may differ.
What Guideline 3.1.1 actually requires
Guideline 3.1.1 is the core of Apple's payment rules: "If you want to unlock features or functionality within your app ... you must use in-app purchase" (App Store Review Guidelines, 3.1.1). Apple's examples are subscriptions, in-game currencies, game levels, access to premium content and unlocking a full version.
In the current version of the guidelines (last updated June 8, 2026), the section also says:
- No home-made unlock mechanisms: license keys, QR codes, augmented reality markers, cryptocurrencies and crypto wallets may not unlock content or features.
- Restore and expiry: credits and in-game currencies bought via IAP may not expire, and restorable purchases need a restore mechanism.
- Digital gift cards and vouchers that are redeemed for digital goods can only be sold in the app via IAP. Physical gift cards mailed to customers may use other payment methods.
- Tips: apps may use IAP currencies to let customers tip the developer or digital content providers in the app.
The reviewer's test: is the thing being paid for used or consumed inside the app? If yes, Apple expects IAP, unless an exception in 3.1.3 or 3.1.4 applies or a regional rule lets you offer something else. Paywall and subscription disclosure rules are covered in our 3.1.2 Subscriptions guide.
Common reasons apps get rejected under 3.1.1
| Trigger | What the reviewer sees |
|---|---|
| Web checkout for digital content | "Upgrade to Pro" opens Stripe, Paddle, PayPal or your own checkout, in a WebView or in Safari. |
| Purchase calls to action | "Subscribe on our website" – with or without a link – or web prices in a storefront where that isn't allowed, including your App Store description (see 2.3 Accurate Metadata). |
| Access codes and license keys | A field for codes bought elsewhere – typical for course platforms, B2B tools and hardware companion apps. |
| Login-only access to web plans | Users sign in with a plan bought on your site, the app offers no IAP for it, and it doesn't qualify as a reader, enterprise or free stand-alone app. |
| Group classes and recorded courses | One-to-many live classes or on-demand videos paid through your own provider. |
| Boosts and in-app ads | Promoted posts, profile boosts or ad placements shown in the same app, paid by card – 3.1.3(g) requires IAP for these. |
| Missing restore | Non-consumables or subscriptions without a Restore Purchases option. |
| IAP for physical goods | Food orders, tickets or merchandise sold through IAP, although 3.1.3(e) requires another payment method. |
Rejected or stuck? Talk to an App Specialist – for free.
Book a free consultation call: we look at your rejection or setup, explain the fastest way forward and tell you honestly whether you need us. Prefer to hand it off? Book our AI-powered + human-powered service and we take care of it.
Digital or physical? The exceptions in 3.1.3 and 3.1.4
If your business model fits one of these clauses, name it explicitly in your review notes.
| Clause | Who qualifies | What is allowed |
|---|---|---|
| 3.1.3(a) Reader apps | Magazines, newspapers, books, audio, music, video | Access to previously purchased content, free-tier sign-up, account management. An informational link needs the External Link Account Entitlement, except on the US storefront. |
| 3.1.3(b) Multiplatform services | Products also sold on web, Android or desktop | Access to items bought elsewhere, provided they are also available as IAP in the app. |
| 3.1.3(c) Enterprise services | Sold directly to organizations for employees or students | Access without IAP. Consumer, single-user or family sales need IAP. |
| 3.1.3(d) Person-to-person | Real-time services between two individuals: tutoring, medical consultations, real estate tours, fitness training | Your own payment provider. One-to-few and one-to-many real-time services need IAP. |
| 3.1.3(e) Goods and services outside the app | Physical goods, rides, deliveries, tickets | You must use Apple Pay, card entry or similar – not IAP. |
| 3.1.3(f) Free stand-alone apps | Free companions to paid web tools (VoIP, cloud storage, email, web hosting) | No IAP, as long as there is no purchasing in the app and no call to action to buy outside. |
| 3.1.3(g) Advertising management apps | Apps whose sole purpose is buying and managing ad campaigns across media | No IAP. Ads or boosts displayed in the same app still need IAP. |
| 3.1.4 Hardware-specific content | Features that depend on specific hardware, such as a telescope | Unlock without IAP. Optional features used with an approved physical product (such as a toy) also need an IAP option. |
Apps using a 3.1.3 exception still may not encourage users inside the app to buy elsewhere – except on the US storefront and via the 3.1.1(a) and 3.1.3(a) entitlements. Emailing your existing users about other purchase options outside the app is allowed. An in-app prompt that collects email addresses in order to send purchase links is only explicitly granted to holders of the Music Streaming Services Entitlement, so avoid it outside the US.
Older articles may cite 3.1.5 for physical goods. In the current guidelines that rule is 3.1.3(e); 3.1.5 now covers cryptocurrency apps (wallets, mining, exchanges).
External purchase links by region (as of October 2026)
Rules differ per App Store storefront and keep changing. Treat this as an October 2026 snapshot and check the linked Apple pages before you ship.
United States storefront
Since the April 30, 2025 contempt order in Epic v. Apple, guidelines 3.1.1(a) and 3.1.3 say the ban on buttons, external links and other calls to action does not apply to apps on the United States storefront, and no entitlement is needed there. In December 2025 the Ninth Circuit upheld the contempt finding but changed the remedy. According to legal coverage of the ruling, Apple may eventually charge a commission limited to costs that are "genuinely and reasonably necessary", and may keep developer links from being more prominent than its own purchase option. The details are still open: the district court has to set them, and according to press reports the US Supreme Court agreed in June 2026 to hear Apple's appeal on the contempt standard, with oral argument not expected before early 2027. The US rules may change again.
- You may add buttons or links to your own web checkout and mention web prices in the app.
- As written, the exemption covers buttons, links and calls to action. It doesn't allow card processing for digital goods inside the app; 3.1.1 itself is unchanged.
- The guidelines don't explicitly say you may drop IAP for digital goods sold in the app. Outside reader apps, the lowest-risk setup is IAP plus an optional web link.
- If your app is available in other countries, show the link only when the App Store storefront is the US – not based on device language, region setting or IP address.
European Union
Apple's EU terms changed again on October 1, 2026 (Apple Developer Program License Agreement updated August 18, 2026). Apps on EU storefronts can sell digital goods through IAP, alternative payment processing inside the app and/or out-of-app offers. According to Apple's Payment options on the App Store in the EU page:
- Any alternative option requires the StoreKit External Purchases or Offers Entitlement (
com.apple.developer.storekit.custom-purchase-link.allowed-regionswith two-letter country codes). In-app processing and tappable links must use theExternalPurchaseCustomLinkAPI, which shows a system disclosure sheet. The entitlement works on iOS and iPadOS 26.2 and later. - When IAP is shown next to other options, it must be at least as prominent. Your App Store product page may not mention alternative payment options.
- Once chosen, your combination of payment options must stay the same across all EU storefronts for 12 months.
- Commissions apply to every route, including sales made within 7 days of a tap on an out-of-app offer link. You report non-IAP transactions to Apple.
- Child-safety rules apply: parental gates for minors, and no out-of-app offers for children under 13 (a higher age in some storefronts) or in Kids category apps.
- Multiplatform apps (3.1.3(b)) must still offer IAP and/or in-app alternative processing – a web link alone is not enough.
Japan and Brazil
On iOS 26.2 and later in Japan and iOS 26.5 and later in Brazil, apps can offer in-app payments through an alternative processor and out-of-app offers in addition to IAP. Both use the StoreKit External Purchases or Offers Entitlement and the ExternalPurchaseCustomLink API with a disclosure sheet. IAP must be offered on every screen that sells a digital good with a payment option, at least as prominently as any alternative. The product page may not mention web or alternative purchases, and commissions apply. Details: Japan, Brazil.
Other entitlement programs
Apple's External Purchase documentation also lists third-party payment providers in South Korea, dating apps in the Netherlands, external purchase links in Russia and music streaming apps in the EEA. Each program has its own entitlement, which must be granted and added to the app before you submit, and its own commission terms.
All other storefronts
Apps and their metadata may not include buttons, external links or other calls to action that lead to non-IAP purchase methods. That covers in-app copy such as "subscribe on our website" even without a link, plus the description, promotional text and screenshots.
How to fix a 3.1.1 rejection step by step
- Find the exact trigger. The message usually names the product or screen after "Specifically". Search for every path to payment: checkout URLs,
UIApplication.shared.opencalls to pricing pages, WebView routes like/checkout, code-redemption fields and "upgrade on our website" copy. - Classify every paid item. Digital and used in the app: IAP. Physical goods or real-world services: your own provider. Exceptions: note the exact sub-clause.
- Set up IAP in App Store Connect. The Account Holder must accept the Paid Apps Agreement under Business > Agreements, including tax and banking details. Then open Apps > [your app] > Monetization > In-App Purchases (or Subscriptions) and add products with stable product IDs, prices, localized display names and a review screenshot. The first consumable, non-consumable, auto-renewable and non-renewing subscription must each be submitted with a new app version, so add them to the version before you submit.
- Implement StoreKit 2. Load products with
Product.products(for:), buy withproduct.purchase(), check theVerificationResult, unlock, then calltransaction.finish(). Listen toTransaction.updatesfrom launch, readTransaction.currentEntitlementsfor state and add a visible Restore Purchases button that callsAppStore.sync(). - Connect IAP to your backend. For accounts shared with your web product, verify signed transactions with the App Store Server API and subscribe to App Store Server Notifications V2, so renewals, refunds and cancellations update the account.
- Remove or gate external calls to action. Without an entitlement and outside the US, remove every button, link and "buy on our website" text. For a US-only link, check
await Storefront.current?.countryCode == "USA"(StoreKit uses three-letter ISO 3166-1 codes) – not device locale or IP. In entitlement regions, use that program's API, such asExternalPurchaseCustomLink.isEligible(EU, Japan, Brazil) orExternalPurchaseLink.canOpen(single-link programs). - Replace unlock codes with App Store offer codes, which now work for all IAP types (consumables, non-consumables, non-renewing and auto-renewable subscriptions) and can be redeemed in the app via StoreKit's redemption sheet.
- Clean up metadata. App Store metadata is set per localization, not per storefront, and a localization such as English (U.S.) can appear in many countries. Keep web prices and purchase calls to action out of the description, promotional text and screenshots unless every storefront showing that localization allows them.
- Test with a StoreKit configuration file in Xcode, then in the sandbox. Development and TestFlight builds both use it, and a Sandbox Apple Account (Settings > Developer) gives you controls such as renewal rate and clearing purchase history. Cover purchase, restore, renewal, cancellation and sign-in on a second device.
How to respond to App Review or appeal
Reply on the rejected submission in App Store Connect (App Review in the app's sidebar):
- You fixed it: upload a new build and state which products now use IAP, where the Restore button is and that external links are removed or limited to the US storefront. List product IDs and add a working demo account (see 2.1 Information Needed).
- An exception applies: argue with facts – what is sold, who delivers it, where it is consumed. "Sessions are live video calls between one student and one tutor, paid per session (3.1.3(d))" beats "we are a service app".
Reviewers sometimes misread a flow. A short screen recording attached in the App Review Information section often saves a round trip. If App Review upholds a decision you're convinced is wrong, appeal to the App Review Board. An appeal won't change the payment rules; it helps when you genuinely fit an exception.
WebView, Flutter and React Native apps
- WebView, Capacitor and Cordova apps often load the full website, including pricing page and checkout. Detect the app (custom user-agent suffix or JavaScript bridge flag) and hide web purchase flows or replace them with a native IAP sheet. If the app is mostly web content, also read our 4.2 Minimum Functionality guide.
- Flutter: the official
in_app_purchaseplugin wraps StoreKit. CallcompletePurchaseafter delivering every purchase markedpendingCompletePurchase, otherwise the transaction is never finished and keeps coming back. - React Native and Expo: libraries such as
react-native-iapneed a development build; Expo Go can't run native purchase modules. - Shared accounts: keep one server-side entitlement per user with its source (Apple, Stripe, Google Play). Users who subscribed elsewhere see a neutral note – without price or link outside the US storefront.
How to prevent 3.1.1 rejections next time
- Keep a monetization map: every paid item, its type, the guideline clause and the payment method per storefront.
- Add CI checks: scan the iOS build and remotely loaded web bundles for checkout domains such as
checkout.stripe.comorbuy.stripe.comand phrases like "subscribe on our website"; fail the pipeline if they appear outside storefront-gated code. - Automate paywall tests against a StoreKit configuration file, so missing products or restore buttons surface before review.
- Re-check regional rules before each release – they changed several times in 2025 and 2026.
AI-assisted checks handle the tedious part: scanning code, web bundles, metadata and screenshots for purchase calls to action. Judgment calls – is a service really one-to-one, do you qualify as a reader app – still need an experienced human. That combination is how appsubmitter.io works; for a second pair of eyes on your payment flows, book a free consultation call.
Template: how to reply to App Review
Adapt this template to your situation. Keep it factual, short and specific – and only claim what you have actually changed.
Checklist before you resubmit
- Every digital item used in the app (subscriptions, credits, premium content, unlocks, tips) can be bought via In-App Purchase.
- New IAP products have complete metadata and a review screenshot, and the first product of each type is added to this app version.
- The Paid Apps Agreement is active in App Store Connect under Business > Agreements, with tax and banking details complete.
- A visible Restore Purchases option works for non-consumables and subscriptions.
- No license keys or access codes unlock content; promotions use App Store offer codes.
- Physical goods and real-world services are paid outside IAP.
- External purchase links and "buy on our website" text appear only in permitted storefronts, gated by the App Store storefront rather than device locale.
- Any regional entitlement is granted, included in the entitlements file and uses the Apple disclosure sheet; in the EU, the payment option rules and parental gates are in place.
- The App Store description, promotional text and screenshots contain no web prices or purchase calls to action for storefronts that do not allow them.
- Web pricing pages and checkout flows are hidden inside any WebView.
- Purchase, restore, renewal and cross-device sign-in were tested in the sandbox with a development or TestFlight build.
Frequently asked questions
Can I link to my website for cheaper subscriptions in 2026?
Do physical products and services need In-App Purchase?
Can I use Apple Pay instead of In-App Purchase for digital content?
Can users log in to a subscription they bought on my website?
Do coaching, tutoring or telehealth apps need In-App Purchase?
Can I use Stripe or PayPal inside my iOS app?
Official source: App Store Review Guidelines – 3.1.1 In-App Purchase. Store policies change regularly – always check the current version. This guide is independent advice and not affiliated with Apple or Google.